kvkk-denetim
Audit KVKK Privacy Compliance
Turkish teams need fast checks for KVKK notices, consent forms, and privacy policies. This skill reviews required elements, flags gaps, and drafts practical compliance text.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "kvkk-denetim" from https://skillstore.io/skills/cesareth-kvkk-denetim.md and its manifest at https://skillstore.io/api/skills/cesareth-kvkk-denetim/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "kvkk-denetim". A privacy notice has no retention period and does not mention Article 11 rights.
Expected outcome:
Critical gaps: Article 11 rights are missing. Important gaps: retention details are missing. Suggested fix: add rights, contact method, and retention schedule.
Using "kvkk-denetim". A consent form says users accept data processing by using the service.
Expected outcome:
Finding: consent is likely invalid because passive use is not explicit consent. Suggested fix: request separate, informed, and withdrawable consent.
Using "kvkk-denetim". A service uses Stripe and Google Cloud for Turkish customer data.
Expected outcome:
Important issue: possible international transfer. Review KVKK Article 9 requirements, transfer notices, legal basis, and provider safeguards.
Security Audit
SafeAll five static findings are false positives caused by Markdown fenced examples in SKILL.md. I found no prompt injection, data exfiltration intent, or business-logic abuse. The bundled Python script performs local text and file analysis only.
Risk Factors
⚙️ External commands (5)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/cesareth-kvkk-denetim/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/cesareth-kvkk-denetim?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/cesareth-kvkk-denetim?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/cesareth-kvkk-denetim/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/cesareth-kvkk-denetim.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
cesareth. (2026). kvkk-denetim security audit report (audit version 4) [Author version 1.0]. Skillstore. https://skillstore.io/skills/cesareth-kvkk-denetim/audits/4BibTeX citation
@techreport{cesareth-cesareth-kvkk-denetim-2026,
author = {cesareth},
title = {kvkk-denetim security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/cesareth-kvkk-denetim/audits/4},
note = {Author version 1.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "kvkk-denetim security audit report (audit version 4)"
version: "1.0"
type: report
authors:
- name: "cesareth"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/cesareth-kvkk-denetim/audits/4"
identifiers:
- type: other
value: "skillstore:cesareth-kvkk-denetim:audit:4"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Review Product Data Flows
Check app signup, support, and analytics data flows before publishing a privacy notice.
Find Notice Gaps
Identify missing KVKK Article 10 and Article 11 elements in existing customer notices.
Draft First Policies
Create a first draft of an aydınlatma metni and explicit consent statement.
Try These Prompts
Review this Turkish privacy notice for KVKK Article 10 completeness. List missing elements, risk level, and plain-language fixes: [paste text]
Draft a Turkish explicit consent statement for this processing activity. Include data type, purpose, withdrawal right, date, name, and signature fields: [describe activity]
Audit this service workflow for KVKK compliance. Check data inventory, legal basis, transfers, retention, Article 11 rights, and security controls: [describe workflow]
Use the KVKK checklist and reference articles to produce a prioritized remediation plan. Group findings by critical, important, and recommended actions: [paste audit notes]
Best Practices
- Provide the full Turkish text and describe the real data flow before asking for review.
- Validate generated legal text with a qualified Turkish privacy lawyer before publication.
- Keep KVKK penalty amounts, VERBİS thresholds, and regulatory guidance current.
Avoid
- Do not treat the generated report as binding legal advice.
- Do not use generic GDPR wording without adapting it to KVKK requirements.
- Do not rely only on keyword checks for high-risk or special-category data processing.
Frequently Asked Questions
Does this skill provide legal advice?
Can it create a KVKK aydınlatma metni?
Can it review existing privacy policies?
Does it work for GDPR compliance?
Does the script send data to external services?
What information should I provide?
Developer Details
Author
cesarethLicense
MIT
Author version
v1.0
Skillstore revision
r1
Version notice
The author-declared version is not valid SemVer.
Ref
dd4a3ef9f20ddf38830950b4bb713df96b431fd6
Maintenance freshness
7/18/2026
Usage
8 downloads · 128 views
File structure